Avast WEBforum

Other => Viruses and worms => Topic started by: Patrick2 on July 10, 2017, 03:33:47 AM

Title: Real or False Positive? still running scans to find out for sure
Post by: Patrick2 on July 10, 2017, 03:33:47 AM
Hi All

Recently did clean install of Avast, was moving files around from possibly dying external drive, decided to run full scan, and got an alert on possible infection (checking with Malwarebyes in about 3-4 minutes)

*Note Previously tried out Windows Defender for a bit after a local friend was like try it*, but don't see how I would get infected, as I did same surfing I did in the past*


Virustotal results

https://www.virustotal.com/en/file/feea416e5e5c8aa81416b81fb25132d1c18b010b02663a253338dbdfb066e122/analysis/1499651193/

Only AVG and Avast Detected it as
Other:Malware-gen [Trj]
(False positive listed as)

Title: Re: Real or False Positive? still running scans to find out for sure
Post by: mchain on July 10, 2017, 04:27:21 AM
Identical detections with another avast user here:  https://forum.avast.com/index.php?topic=205279.0 (https://forum.avast.com/index.php?topic=205279.0)
Title: Re: Real or False Positive? still running scans to find out for sure
Post by: jefferson sant on July 10, 2017, 04:30:37 AM
Hello.

I confirm that this is an FP.Scan the origin and showed the same detection.

Attached

Title: Re: Real or False Positive? still running scans to find out for sure
Post by: REDACTED on July 10, 2017, 04:31:06 AM
Oh, hello! Sorry that I didn't notice this topic, but the topic title didn't highlight this being same issue as with me :-[
Title: Re: Real or False Positive? still running scans to find out for sure
Post by: Patrick2 on July 10, 2017, 04:32:55 AM
Yes I should've probably titled it differently than I did, my bad
Title: Re: Real or False Positive? still running scans to find out for sure
Post by: jefferson sant on July 10, 2017, 04:39:41 AM
I sent mine through the report

https://www.avast.com/false-positive-file-form.php

Reported to Vírus analyst ~
Title: Re: Real or False Positive? still running scans to find out for sure
Post by: Patrick2 on July 10, 2017, 04:47:59 AM
Same sent in a report also to Avast

Title: Re: Real or False Positive? still running scans to find out for sure
Post by: LukasJ on July 10, 2017, 09:34:41 AM
Hi, detection was disabled.
Will be solved in next stream update. (5 minutes)

Lukáš
Title: Re: Real or False Positive? still running scans to find out for sure
Post by: Patrick2 on July 10, 2017, 06:30:38 PM
Thank you Lukas on fixing this in a timely manner
Title: Re: Real or False Positive? still running scans to find out for sure
Post by: REDACTED on July 14, 2017, 01:25:23 AM
Sorry to resurrect an older thread, I've only just noticed I had two desktop.ini files move to the vault on the 10th too, and they're still being flagged as Other:Malware-gen [Trj] in the virus vault. I've submitted them to the lab.
Title: Re: Real or False Positive? still running scans to find out for sure
Post by: jefferson sant on July 15, 2017, 12:48:25 AM
Sorry to resurrect an older thread, I've only just noticed I had two desktop.ini files move to the vault on the 10th too, and they're still being flagged as Other:Malware-gen [Trj] in the virus vault. I've submitted them to the lab.

I do not suppose it's the same local reported, you should get the answer soon.
Title: Re: Real or False Positive? still running scans to find out for sure
Post by: REDACTED on July 15, 2017, 11:13:25 AM
Well, it was in the same location as the person in the other thread (https://forum.avast.com/index.php?topic=205279.0), "C:\Users\*my name*\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini" so I assume if it's an fp for him, it is for me. An MBAM scan found nothing.
Title: Re: Real or False Positive? still running scans to find out for sure
Post by: jefferson sant on July 17, 2017, 09:50:26 PM
Well, it was in the same location as the person in the other thread (https://forum.avast.com/index.php?topic=205279.0), "C:\Users\*my name*\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini" so I assume if it's an fp for him, it is for me. An MBAM scan found nothing.

What is the version Avast and number of VPS ?